We are seeking an experienced Senior Manager, Cybersecurity – Governance, Risk & Compliance (GRC) to provide strategic leadership across the organization's cybersecurity program.
This role will lead the development and advancement of the organization's cybersecurity strategy, governance, risk management, compliance, and security initiatives, ensuring organizational assets are protected, regulatory and industry requirements are met, and the overall security posture continues to mature.
The Senior Manager will serve as a trusted cybersecurity advisor to IT leadership, Executive Management, and senior business stakeholders, translating complex cybersecurity and technology risks into clear business priorities, strategic recommendations, and actionable plans.
The role will provide broad oversight across GRC, security operations, incident response, cyber resilience, cloud security, third-party risk, and the secure adoption of AI and emerging technologies.
Key Responsibilities
Cybersecurity Strategy & Leadership
- Develop and execute a multi-year cybersecurity strategy, roadmap, and operating model aligned with business objectives and enterprise risk.
- Establish cybersecurity priorities, investment plans, budgets, and business cases.
- Define cybersecurity KPIs and KRIs to measure risk, control effectiveness, program maturity, and overall performance.
- Continuously monitor emerging threats, technologies, vulnerabilities, and changes in the cybersecurity landscape.
- Identify opportunities to strengthen the organization's overall security maturity and resilience.
Governance, Risk & Compliance
- Lead the organization's Cybersecurity GRC program, including:
- Enterprise cybersecurity risk assessments
- Risk registers
- Policies and standards
- Control frameworks
- Risk remediation
- Compliance monitoring
- Executive reporting
- Establish and maintain effective cybersecurity governance structures, policies, standards, and procedures.
- Lead cybersecurity audits, regulatory reviews, customer security assessments, and compliance initiatives.
- Provide oversight of cybersecurity controls and ensure identified gaps are appropriately remediated.
- Maintain alignment with recognized frameworks and standards including NIST, ISO 27001, CIS Controls, and SOC 2.
AI & Emerging Technology Security
- Lead cybersecurity strategy and governance for the secure adoption of Artificial Intelligence, Generative AI, machine learning, automation, and other emerging technologies.
- Assess cybersecurity, privacy, data, and third-party risks associated with AI-enabled technologies and emerging platforms.
- Establish governance requirements for responsible AI and Generative AI use, including:
- Data protection
- Access controls
- Model security
- Monitoring
- Risk management
- Partner with Technology, Data, Privacy, Legal, and business teams to establish secure-by-design principles for AI and emerging technologies.
- Identify opportunities to use AI and automation to enhance threat detection, security monitoring, incident response, vulnerability management, and security operations.
- Monitor emerging cyber threats involving AI and develop appropriate controls, detection capabilities, and response strategies.
Executive Advisory & Reporting
- Serve as a trusted cybersecurity advisor to the CIO, IT leadership, Executive Management, and senior business stakeholders.
- Translate technical cybersecurity risks into clear business impacts, priorities, and recommendations.
- Prepare and present cybersecurity risk, compliance, maturity, and strategic updates to Executive Management and the Board.
- Provide leadership with actionable recommendations regarding cybersecurity investments and risk priorities.
Security Operations & Cyber Resilience
- Provide executive oversight of cybersecurity incident response, cyber resilience, tabletop exercises, and major incident reviews.
- Oversee the performance of outsourced Security Operations Center (SOC)/MSSP providers.
- Provide governance and oversight across:
- Security monitoring
- Threat detection
- Incident response
- Vulnerability management
- Threat intelligence
- Ensure appropriate processes are in place to prepare for, respond to, and recover from significant cyber incidents.
Third-Party & Supply Chain Risk
- Lead third-party and supply-chain cybersecurity risk management.
- Establish security requirements and assessment processes for vendors and strategic partners.
- Review and assess cybersecurity risks associated with critical third parties and service providers.
- Partner with Procurement, Legal, Risk, and business stakeholders to embed cybersecurity requirements into vendor management and contracting processes.
Enterprise Security Governance
Provide cybersecurity governance and risk oversight across:
- Cloud environments
- Infrastructure
- Applications
- Data
- Identity and access management
- AI and emerging technologies
- Enterprise technology architecture
Partner with Technology, Business, Legal, Privacy, Risk, Internal Audit, Procurement, and external providers to embed cybersecurity into business and technology decisions.
Team Leadership
- Lead, mentor, and develop cybersecurity professionals.
- Build a high-performing, collaborative, and sustainable cybersecurity organization.
- Establish clear objectives, accountability, and professional development opportunities for team members.
Qualifications & Experience
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
- 12+ years of progressive cybersecurity/information security experience, including at least 5 years in a leadership or management capacity.
- Strong experience in:Cybersecurity strategy
- Governance, Risk & Compliance
- Enterprise risk management
- Security assurance
- Security program management
- Demonstrated experience overseeing SOC/MSSP relationships and cybersecurity operations.
- Strong understanding of cybersecurity risks associated with AI, cloud, automation, and emerging technologies.
- Experience balancing innovation with security, privacy, regulatory, and enterprise risk requirements.
- Demonstrated experience in incident response, cyber resilience, and security program management.
- Experience presenting cybersecurity strategy and risk to senior executives and/or Boards.
- Experience supporting audits, regulatory reviews, customer security assessments, and cybersecurity compliance programs.
- Experience with cloud security and cybersecurity architecture.
- Experience developing cybersecurity budgets, business cases, KPIs/KRIs, and investment priorities.
- Strong knowledge of recognized cybersecurity frameworks, including NIST, ISO 27001, CIS Controls, and SOC 2.
Preferred Certifications
One or more of the following certifications would be considered an asset:
- CISSP
- CISM
- CRISC
- CCSP
- GIAC
- Other recognized cybersecurity, information security, risk, or audit certifications
What Success Looks Like
Success in this role will be demonstrated through:
- Increased cybersecurity maturity and improved enterprise risk posture
- Strong cybersecurity governance and executive visibility
- Effective identification, prioritization, and reduction of material cyber risks
- Strong audit, compliance, and regulatory outcomes
- Effective third-party and supply-chain cybersecurity risk management
- Improved cyber incident preparedness, response, and resilience
- Successful execution of the cybersecurity strategy and roadmap
- Responsible and secure adoption of AI and emerging technologies
- A strong, capable, and sustainable cybersecurity team
Candidates must be eligible to work in Canada
I would like to thank all the candidates in advance. Please do stay connected on LinkedIn for future opportunities. Shortlisted candidates will be contacted .
This position reflects a current vacancy with one of our clients. Our Recruiters combine their expertise and AI-enabled technology in the recruitment process.